GEN003790 - The services file must not have an extended ACL.

Information

The services file is critical to the proper operation of network services and must be protected from unauthorized modification. If the services file has an extended ACL, it may be possible for unauthorized users to modify the file. Unauthorized modification could result in the failure of network services.

Solution

Remove the extended ACL from the file.
# setfacl --remove-all /etc/services

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-000225, Rule-ID|SV-63985r1_rule, STIG-ID|GEN003790, Vuln-ID|V-22428

Plugin: Unix

Control ID: a3dbed93c71a5499c3639fe4fbce7e2c774dae4bc42407683f032f88b2104b77